CVE-2026-4176 Details
Description
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.
A vulnerability exists in the Perl dual-life core module Compress::Raw::Zlib, affecting versions from 5.9.4 prior to 5.40.4-RC1, and from 5.41.0 prior to 5.42.2-RC1. The issue arises from a bundled version of zlib that contains multiple vulnerabilities, including those identified in CVE-2026-27171. This vulnerability in zlib was highlighted in a 7ASecurity audit. The problem has been addressed in Compress::Raw::Zlib version 2.220, which is included in Perl 5.40.4-RC1 and 5.42.2-RC1.
Users can upgrade to Compress::Raw::Zlib version 2.220 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Perl/perl5/commit/c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94 | CPANSec | Patch |
| https://lists.security.metacpan.org/cve-announce/msg/37638919/ | CPANSec | Third Party Advisory |
| https://metacpan.org/release/PMQS/Compress-Raw-Zlib-2.221/source/Changes | CPANSec | Release Notes |
| https://metacpan.org/release/SHAY/perl-5.40.4/changes | CPANSec | Release Notes |
| https://metacpan.org/release/SHAY/perl-5.42.2/changes | CPANSec | Release Notes |
| https://www.cve.org/CVERecord?id=CVE-2026-3381 | CPANSec | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/03/30/2 | CVE | Mailing ListThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| perl perl | >= 5.9.4, < 5.40.4 >= 5.41.0, < 5.42.2 >= 5.43.0, < 5.43.9 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CPANSec |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | Initial Analysis | [email protected] |
| Mar 30, 2026 | CVE Modified | CISA-ADP |
| Mar 30, 2026 | CVE Modified | CVE |
| Mar 29, 2026 | New CVE Received | CPANSec |